IP Library › Granted Patent US 12,348,436
Granted Patent B2
US 12,348,436 · App. 18/644,315 · Granted Jul 1, 2025

Intelligent quarantine on switch fabric for physical and virtualized infrastructure

Inventors: Balaji Sundararajan (Fremont, CA); Gaurang Rajeev Mokashi (Sunnyvale, CA); Preety Mordani (Fremont, CA); Vivek Agarwal (Campbell, CA)
Assignee: Cisco Technology, Inc.
H04L49/25G06F9/45558H04L43/08H04L43/20H04L47/20H04L63/1416H04L63/20G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,436
App. No.
18/644,315
Granted
Jul 1, 2025
Kind
B2
Abstract

Systems, methods, and computer-readable media for performing threat remediation through a switch fabric of a virtualized network environment. Data traffic passing into a virtualized network environment including a plurality of virtual machines running on a switch fabric is monitored. A network threat introduced through at a least a portion of the data traffic is identified at the switch fabric. One or more remedial measures are performed in the network environment based on the identification of the network threat in the virtualized network environment.

Claims (51)

1. A method comprising:

monitoring, at one or more network nodes of a virtualized network environment, data traffic passing into the virtualized network environment, wherein the virtualized network environment includes a plurality of workloads hosted in the virtualized network environment;

identifying, using a first network node of the one or more network nodes of the virtualized network environment, a Denial of Service (DOS) (DDeS) attack introduced into the virtualized network environment through at least a portion of the data traffic passing into the virtualized network environment, the first network node receiving the at least a portion of the data traffic introducing a network threat; and

performing one or more remedial measures in the virtualized network environment based on the identification of the DoS attack in the virtualized network environment, at least one of the one or more remedial measures comprising:

generating DoS threat information including a signature of the data traffic associated with the network traffic; and

distributing the DoS threat information to at least a second network node of the one or more network nodes of the virtualized network environment.

2. The method of claim 1 , further comprising:

intercepting the at least a portion of the data traffic introducing the DoS attack into the virtualized network environment; and

performing the one or more remedial measures while the at least a portion of the data traffic remains in the virtualized network environment.

3. The method of claim 1 , wherein the one or more remedial measures further includes quarantining, in the virtualized network environment, the at least a portion of the data traffic introducing the DoS in the virtualized network environment.

4. The method of claim 1 , wherein the one or more remedial measures comprises preventing transmission of the at least a portion of the data traffic introducing the DoS attack to the workloads in the virtualized network environment.

5. The method of claim 4 , wherein the workloads are virtual machines; the remedial measures further comprising preventing transmission of the at least a portion of the data traffic introducing the DoS attack to one or more hypervisors hosting the workloads in the virtualized network environment.

6. The method of claim 1 , wherein the DoS threat information includes one or a combination of an identification of a source of the at least a portion of the data traffic introducing the DoS attack into the virtualized network environment, a signature of the at least a portion of the data traffic, and an identification of characteristics of the at least a portion of the data traffic.

7. The method of claim 1 , further comprising:

matching the at least a portion of the data traffic introducing the DoS attack to a known network threat based on a signature of the at least a portion of the data traffic and a signature of the known network threat; and

identifying the network threat in the at least a portion of the data traffic based on a matching of the at least a portion of the data traffic to the known network threat.

8. A system comprising:

one or more processors; and

at least one non-transitory computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

monitoring, at one or more network nodes of a virtualized network environment, data traffic passing into the virtualized network environment,

wherein the virtualized network environment includes including a plurality of workloads hosted in the virtualized network environment;

identifying, using a first network node of the one or more network nodes of the virtualized network environment, a Denial of Service (DoS) attack introduced into the virtualized network environment through at least a portion of the data traffic passing into the virtualized network environment, the first network node receiving the at least a portion of the data traffic introducing a network threat; and

performing one or more remedial measures in the virtualized network environment based on the identification of the DoS attack in the virtualized network environment, at least one of the one or more remedial measures comprising:

generating DoS threat information including a signature of the data traffic associated with the network traffic; and

distributing the DoS threat information to at least a second network node of the one or more network nodes of the virtualized network environment.

9. The system of claim 8 , the operations further comprising:

intercepting the at least a portion of the data traffic introducing the DoS attack into the virtualized network environment; and

performing the one or more remedial measures while the at least a portion of the data traffic remains in the virtualized network environment.

10. The system of claim 8 , wherein the one or more remedial measures further includes quarantining, in the virtualized network environment, the at least a portion of the data traffic introducing the DoS in the virtualized network environment.

11. The system of claim 8 , wherein the one or more remedial measures comprises preventing transmission of the at least a portion of the data traffic introducing the DoS attack to the workloads in the virtualized network environment.

12. The system of claim 11 , wherein the workloads are virtual machines; the remedial measures further comprising preventing transmission of the at least a portion of the data traffic introducing the DoS attack to one or more hypervisors hosting the workloads in the virtualized network environment.

13. The system of claim 8 , wherein the DoS threat information includes one or a combination of an identification of a source of the at least a portion of the data traffic introducing the DoS attack into the virtualized network environment, a signature of the at least a portion of the data traffic, and an identification of characteristics of the at least a portion of the data traffic.

14. The system of claim 8 , the operations further comprising:

matching the at least a portion of the data traffic introducing the DoS attack to a known network threat based on a signature of the at least a portion of the data traffic and a signature of the known network threat; and

identifying the network threat in the at least a portion of the data traffic based on a matching of the at least a portion of the data traffic to the known network threat.

15. A non-transitory computer-readable storage medium having stored therein instructions which, when executed by a processor, cause the processor to perform operations comprising:

monitoring, at one or more network nodes of a virtualized network environment, data traffic passing into the virtualized network environment, wherein the virtualized network environment includes a plurality of workloads hosted in the virtualized network environment;

identifying, using a first network node of the one or more network nodes of the virtualized network environment, a Denial of Service (Dos) attack introduced into the virtualized network environment through at least a portion of the data traffic passing into the virtualized network environment, the first network node receiving the at least a portion of the data traffic introducing a network threat; and

performing one or more remedial measures in the virtualized network environment based on the identification of the DoS attack in the virtualized network environment, at least one of the one or more remedial measures comprising:

generating DoS threat information including a signature of the data traffic associated with the network traffic; and

distributing the DoS threat information to at least a second network node of the one or more network nodes of the virtualized network environment.

16. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

intercepting the at least a portion of the data traffic introducing the DoS attack into the virtualized network environment; and

performing the one or more remedial measures while the at least a portion of the data traffic remains in the virtualized network environment.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more remedial measures further includes quarantining, in the virtualized network environment, the at least a portion of the data traffic introducing the DoS in the virtualized network environment.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more remedial measures comprises preventing transmission of the at least a portion of the data traffic introducing the DoS attack to the workloads in the virtualized network environment.

19. The non-transitory computer-readable storage medium of claim 18 , wherein the workloads are virtual machines; the remedial measures further comprising preventing transmission of the at least a portion of the data traffic introducing the DoS attack to one or more hypervisors hosting the workloads in the virtualized network environment.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the DoS threat information includes one or a combination of an identification of a source of the at least a portion of the data traffic introducing the DoS attack into the virtualized network environment, a signature of the at least a portion of the data traffic, and an identification of characteristics of the at least a portion of the data traffic.

21. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

matching the at least a portion of the data traffic introducing the DoS attack to a known network threat based on a signature of the at least a portion of the data traffic and a signature of the known network threat; and

identifying the network threat in the at least a portion of the data traffic based on a matching of the at least a portion of the data traffic to the known network threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2024
From: SUNDARARAJAN, BALAJI; MOKASHI, GAURANG RAJEEV; MORDANI, PREETY; AGARWAL, VIVEK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 067206/0917 →
Continuity (5)
Continuation 18594437 · Mar 4, 2024
Continuation 18415423 · Jan 17, 2024
Continuation 18171322 · Feb 17, 2023
Continuation 16826082 · Mar 20, 2020
Related Publication 20240275800A1 · Aug 15, 2024
References Cited (23)
US 9197664B1 · Aziz et al. · 2015 [cited by applicant]
US 9591020B1 · Aziz · 2017 [cited by applicant]
US 11159389B1 · Miriyala et al. · 2021 [cited by applicant]
US 11245721B2 · Konda · 2022 [cited by examiner]
US 11750622B1 · Kim · 2023 [cited by examiner]
US 20100202466A1 · Eswaran · 2010 [cited by examiner]
US 20100212005A1 · Eswaran · 2010 [cited by examiner]
US 20130219497A1 · Lukas et al. · 2013 [cited by applicant]
US 20130219500A1 · Lukas et al. · 2013 [cited by applicant]
US 20160164894A1 · Zeitlin · 2016 [cited by examiner]
US 20160171215A1 · Bank et al. · 2016 [cited by applicant]
US 20170118041A1 · Bhattacharya · 2017 [cited by examiner]
US 20170163685A1 · Schwartz · 2017 [cited by examiner]
US 20170366575A1 · Polepalli · 2017 [cited by examiner]
US 20180006921A1 · Mozes · 2018 [cited by examiner]
US 20180091547A1 · St. Pierre · 2018 [cited by examiner]
US 20180139221A1 · Chen · 2018 [cited by applicant]
US 20180189489A1 · Zhang et al. · 2018 [cited by applicant]
US 20190028505A1 · Shpiner · 2019 [cited by examiner]
US 20190199746A1 · Doron · 2019 [cited by examiner]
US 20200106742A1 · Moore et al. · 2020 [cited by applicant]
US 20200278892A1 · Nainar · 2020 [cited by examiner]
EP 3486775A1 · 2019 [cited by applicant]